199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran
Brief
Mend. io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend. io reported the full batch to RubyGems for takedown. Every gem was pulled within hours.
Mend. io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works. What that deeper look found: real tradecraft wrapped around code that, in both samples examined, doesn’t run at all.
The short version:
199 gems, two accounts, one shared name pool. 181 names are machine-generated nonsense that nobody would ever type into a Gemfile . The other 19 are typosquats of a fully resolved dependency tree, including aws-sdk-core and all four of its direct dependencies.
